VMware vCenter vpxd Events
VMware vCenter Server 8.0 vpxd events forwarded over RFC 5424 syslog and indexed by the Elastic VMware vSphere integration (vsphere.log): API logins and logouts, failed SSO logins, VM power and reconfiguration, and permission changes, with the native syslog line in event.original. About 8,100 records a day from one vCenter: four service accounts around the clock and eight staff accounts on a UTC working day. Recurring episodes show three to five failed SSO logins for one administrator, then that administrator's login and an Admin permission grant.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/virtualization-vmware/generator.yml \
--id vmware \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| vim.event.UserLoginSessionEvent | API session opened | 49.26% of records | authentication |
| vim.event.UserLogoutSessionEvent | Session closed, with login time and number of API calls | 49.24% of records | authentication |
| vim.event.VmPoweredOffEvent | VM powered off | 0.55% of records | host |
| vim.event.VmPoweredOnEvent | The same VM powered on again | 0.55% of records | host |
| vim.event.VmReconfiguredEvent | numCPU or memoryMB changed while the VM is off | 0.17% of records | configuration |
| vim.event.EventEx | Failed SSO login: wrong password for a staff account | 0.11% of records | authentication |
| vim.event.PermissionAddedEvent | Temporary permission created | 0.08% of records | iam |
| vim.event.PermissionRemovedEvent | Expired permission removed | 0.04% of records | iam |
Realism Features
- One vCenter manages one datacenter with twelve VMs on three ESXi hosts. Four service accounts log in and out every few seconds to minutes: a monitoring poller about 2,300 times a day, a metrics collector about 970, an orchestration account about 390 and a backup account about 200. Eight staff accounts (four administrators, two helpdesk operators, two developers) log in about 3-17 times a day each, administrators most.
- About 8,100 records a day, ±3% from day to day: about 7,900 from service accounts at a flat rate and about 220 from staff, 90% of them at 07-17 UTC, 6% at 06-07 and 17-19 and 4% at night. The hour curve repeats every day, with no weekly cycle.
- Staff sessions last a median 10-12 minutes (90th percentile about 30); monitoring poller sessions a median 14 s, metrics collector sessions about 2 minutes, backup sessions about 10 minutes. Records of one session are seconds to minutes apart rather than milliseconds, and logout records carry the login time, duration and number of API calls.
- 7% of staff sessions start with one to five wrong passwords, each extra failure rarer than the previous one, and 12% of those end without a login; service accounts never fail. Runs of three or more failures before a login occur a few times a week in ordinary traffic.
- Administrators and operators power-cycle VMs or change numCPU or memoryMB one step while the VM is off, developers power-cycle test and batch VMs, and every VM powered off is powered on again in the same session. About six temporary grants a day (one or two of them Admin) give five internal role names to eight principals on the datacenter, two clusters, three folders or two VMs; each is removed after a median 36 hours (2 hours to 14 days), with at most one permission per principal and entity.
- Logins and logouts carry the user, source address and user agent fields the Elastic vSphere pipeline derives, failed SSO logins user.name and source.ip. For VM and permission events the pipeline only splits the syslog envelope, so the acting account, VM and principal stay in message and event.original; their wording follows the vCenter event catalog rather than a recorded vCenter log, and reconfiguration is written on one line with CPU and memory changes only.
- Only eight vpxd event classes are present; tasks, alarms, host and cluster events are not. Every account uses one fixed address and user agent Go-http-client/1.1, and the collector fields describe a synthetic Elastic Agent. With anomalies on, runs of three or more failures before a login are about one a day more frequent and Admin grants rise to two or three a day.
Sample Output
{
"@timestamp": "2026-09-01T11:00:13.646Z",
"agent": {
"ephemeral_id": "c4a1df82-7a9c-4a3e-8546-6d7cc04538e6",
"id": "5096d7cc-1e4b-4959-abea-7355be2913a7",
"name": "log-collector-01.lab.example",
"type": "filebeat",
"version": "8.17.0"
},
"client": {
"ip": "10.40.3.22"
},
"data_stream": {
"dataset": "vsphere.log",
"namespace": "default",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "5096d7cc-1e4b-4959-abea-7355be2913a7",
"snapshot": false,
"version": "8.17.0"
},
"event": {
"agent_id_status": "verified",
"category": [
"authentication"
],
"dataset": "vsphere.log",
"id": "674988",
"ingested": "2026-09-01T11:00:14Z",
"kind": "event",
"original": "\u003c14\u003e1 2026-09-01T11:00:13.646579+00:00 vcsa01.lab.example vpxd 36683 - - Event [674988] [1-1] [2026-09-01T11:00:13.646479Z] [vim.event.EventEx] [info] [ops.petrova] [] [674988] [Failed login ops.petrova from 10.40.3.22 at 09/01/2026 11:00:13 GMT in SSO]",
"outcome": "failure",
"timezone": "+00:00",
"type": [
"info"
]
},
"host": {
"architecture": "x86_64",
"containerized": false,
"hostname": "log-collector-01.lab.example",
"id": "3f0b6c1e2d9a4c7f8e5b1a2d3c4e5f60",
"ip": [
"10.40.0.50"
],
"mac": [
"00-50-56-A1-7B-10"
],
"name": "vcsa01.lab.example",
"os": {
"codename": "jammy",
"family": "debian",
"kernel": "5.15.0-122-generic",
"name": "Ubuntu",
"platform": "ubuntu",
"type": "linux",
"version": "22.04.5 LTS (Jammy Jellyfish)"
}
},
"input": {
"type": "udp"
},
"log": {
"level": "info",
"logger": "vim.event.EventEx",
"source": {
"address": "10.40.0.10:59236"
},
"syslog": {
"facility": {
"code": 1,
"name": "User"
},
"priority": 14,
"severity": {
"code": 6,
"name": "Informational"
}
}
},
"message": "[ops.petrova] [] [674988] [Failed login ops.petrova from 10.40.3.22 at 09/01/2026 11:00:13 GMT in SSO]",
"process": {
"name": "vpxd",
"pid": 36683
},
"related": {
"ip": [
"10.40.3.22"
]
},
"source": {
"ip": "10.40.3.22"
},
"tags": [
"preserve_original_event",
"vmware-sphere"
],
"user": {
"name": "ops.petrova"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Emit recurring anomaly episodes; false gives background only |
| anomaly_interval_hours | 24 | Interval between episodes in event time, 6 to 8,760 hours |
| vcenter_host | vcsa01.lab.example | vCenter hostname in the syslog header (host.name) |
| vcenter_ip | 10.40.0.10 | Address the syslog datagrams come from (log.source.address) |
| datacenter | DC-East | Datacenter name in VM and permission messages |
| sso_domain | VSPHERE.LOCAL | SSO domain of all accounts and principals |
| collector_name | log-collector-01.lab.example | Elastic Agent host (agent.name, host.hostname) |
| collector_ip | 10.40.0.50 | Elastic Agent host address |
| collector_mac | 00-50-56-A1-7B-10 | Elastic Agent host MAC address |
| collector_host_id | 3f0b6c1e2d9a4c7f8e5b1a2d3c4e5f60 | Elastic Agent host id |
| agent_id | 5096d7cc-1e4b-4959-abea-7355be2913a7 | Elastic Agent id |
| agent_ephemeral_id | c4a1df82-7a9c-4a3e-8546-6d7cc04538e6 | Elastic Agent ephemeral id |
| agent_version | 8.17.0 | Elastic Agent version |
Related Generators
VMware ESXi hostd logs
ESXi 8 hostd authentication and VM tasks from one host, four administrators and two automated API clients. Native messages sit inside a custom ECS wrapper.
Microsoft Hyper-V VMMS Checkpoint and Merge Failures
Microsoft-Windows-Hyper-V-VMMS-Admin error records for failed VM checkpoints and background disk merges on four Hyper-V hosts with 60 VMs, as Winlogbeat-style ECS JSON with the raw Windows event XML in event.original. About 120 records a day, most of them in the nightly 22:00-05:00 backup window; ten VMs with recurring checkpoint trouble carry most failures. Recurring episodes show one of those VMs with a cancelled checkpoint followed by three failed checkpoint attempts, each followed by a disk merge failure.
Proxmox VE logs
About 12,240 records/day from one node, twelve VMs, administrators, automation accounts and an API-token monitor.